SushiSwap SDK
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is classified as suspicious due to the presence of code in `references/REFERENCE.md` that demonstrates reading `process.env.PRIVATE_KEY` and using it to sign and send blockchain transactions. While presented as an example for developers on how to use the SDK, this instruction, if interpreted and executed by an AI agent, could lead to the agent accessing and utilizing a highly sensitive credential from its environment for transaction execution, representing a significant security risk without clear malicious intent of exfiltration.
